cyber threats faced by banks in Kenya

What are common cyber threats faced by banks in Kenya and how to mitigate them?

Cyber fraud in Kenya’s banking sector more than doubled in one year. Reported cases rose from 153 in 2023 to 353 in 2024, while actual losses increased from KES 412 million to approximately KES 1.59 billion, according to the Central Bank of Kenya (CBK).

At the same time, Kenya’s rapid shift toward mobile and digital banking is expanding the attack surface for fraudsters, ransomware groups, insiders and compromised third parties.

For Kenyan banks, cybersecurity is no longer simply an IT concern. It is a financial, operational, regulatory and reputational risk that increasingly belongs on the boardroom agenda.

Kenya’s Banking Cybersecurity Landscape at a Glance  

KEY METRICLATEST AVAILABLE FIGURE
MtricFigure
Banking cyber-fraud cases, 2024353
Banking cyber-fraud cases, 2023153
Actual fraud losses, 2024KES 1.59 billion
Amount exposed to fraud, 2024KES 1.96 billion
Customers preferring mobile banking, 2021 survey58.5%
Commercial banks ranking cyber risk among top 3 innovation risks92%
Microfinance banks doing the same86%
KE-CIRT/CC cyber-threat events, Apr–Jun 20254.59 billion

CBK recorded 353 reported banking fraud cases in 2025, with KES 1.963 billion exposed and KES 1.594 billion actually lost. Meanwhile, the Communications Authority of Kenya (CA) reported more than 4.59 billion cyber-threat events between April and June 2025.

The takeaway: Kenya’s financial sector is becoming increasingly digital at precisely the moment the threat environment is becoming more complex.

What Are the Biggest Cyber Threats Facing Banks in Kenya?  

The biggest cyber threats facing banks in Kenya are not limited to traditional hacking. Financial institutions are dealing with a combination of mobile banking fraud, SIM-swap attacks, insider threats, ransomware, third-party compromise and large-scale system attacks.

Kenya’s Cyber Threats: Risk Comparison  

THREATPRIMARY TARGETPOTENTIAL IMPACT
SIM-swap & smishingCustomersAccount takeover and financial loss
Insider threatsAccounts and internal systemsFraud and data theft
RansomwareCore systems and endpointsOperational disruption
Third-party compromiseVendors and connected systemsData exposure and lateral access
System-level attacksNetworks, devices and databasesInfrastructure compromise

These threats can also overlap. A compromised employee or contractor account, for example, could provide an attacker with legitimate access that can then be used to steal data or facilitate fraudulent transactions.

1. Mobile Banking: Kenya’s Biggest Cybersecurity Pressure Point?  

Kenya’s mobile-first financial ecosystem has transformed access to banking. But the same convenience has created an attractive target for cybercriminals.

According to the Kenya Bankers Association’s Customer Satisfaction Survey, 58.5% of bank customers preferred mobile banking, compared with 52% in 2020.

The wider mobile-money ecosystem is also enormous. The Communications Authority reported 48.6 million mobile-money subscriptions by September 2025, representing 92.8% penetration.

For attackers, mobile banking offers speed.

A typical SIM-swap attack can follow this pattern:

Social engineering → SIM replacement → OTP interception → Account access → Fraudulent transaction

Smishing adds another layer, with criminals sending messages impersonating banks or trusted organizations to trick customers into revealing credentials or visiting fraudulent websites.

How Banks Can Reduce Mobile Banking Risk  

Banks should move beyond relying solely on SMS-based authentication and combine multiple signals before approving high-risk transactions.

Key controls include:

  • Stronger, app-based authentication
  • Device fingerprinting
  • Behavioural analytics
  • Transaction risk scoring
  • SIM-swap detection
  • Cooling-off periods after SIM changes
  • Step-up authentication for unusual transactions
  • Real-time customer alerts
  • Continuous anti-smishing awareness

The Communications Authority also recommends measures such as multi-factor authentication, strong passwords, regular patching and strengthened security controls as part of cyber-risk management.

The objective is straightforward: a valid credential should not automatically mean a valid transaction.

2. Insider Threats: When the Attacker Already Has Access  

External hackers are only part of Kenya’s banking security challenge.

Employees, agents, contractors and other trusted users can have legitimate access to customer information, applications or transaction systems. That makes insider risk particularly difficult to detect.

CBK’s banking-sector innovation research found that 92% of banks and 86% of microfinance banks identified cyber risk among their top three innovation-related risks. The same research also highlighted third-party and vendor-management risks.

Insider risk does not necessarily mean a malicious employee. It can involve:

  • Compromised credentials
  • Excessive privileges
  • Poor access controls
  • Inadequate monitoring
  • Third-party accounts
  • Deliberate employee or agent collusion

Four Controls Banks Should Prioritize  

Least privilege: Employees should only have access to the information and systems required for their roles.

Segregation of duties: High-risk activities should not be concentrated with one individual.

Behavioural monitoring: Banks should monitor unusual access and transaction patterns rather than relying solely on login failures.

Continuous access reviews: Privileges should be reviewed when employees change roles and immediately when contractors or employees leave.

The key principle is to treat trusted access as a risk that requires continuous verification, rather than assuming legitimate credentials are inherently safe.

3. Ransomware: From Cyber Incident to Banking Outage  

Ransomware is especially dangerous for financial institutions because its impact can extend beyond stolen information.

An attack could potentially result in:

ATM disruption → Mobile banking downtime → Failed transactions → Branch disruption → Customer trust impact

That makes ransomware a business-continuity issue as much as a cybersecurity issue.

Kenya’s wider cyber environment demonstrates the scale of the challenge. During April–June 2025, KE-CIRT/CC recorded approximately 4.59 billion cyber-threat events, including malware and distributed denial-of-service activity.

Common ransomware entry points include:

  • Phishing
  • Compromised credentials
  • Unpatched systems
  • Vulnerable remote-access services
  • Malicious files
  • Compromised third parties

4. Third-Party Risk: The Extended Banking Attack Surface  

Modern banks rely on an extensive network of technology and service providers.

Cloud platforms, payment processors, IT contractors, software vendors and telecommunications providers can all connect to systems or data that banks need to operate.

That creates an extended attack surface.

Kenya’s Cyber Threat Volume Shows the Scale of the Problem  

Banks operate within Kenya’s broader digital ecosystem, so national cyber-threat trends matter.

KE-CIRT/CC recorded 4,586,682,277 cyber-threat events between April and June 2025, representing an 80.70% increase from the previous quarter. More than 4.49 billion of those events were classified as system attacks.

These numbers should be interpreted carefully. A cyber-threat event is not necessarily a successful breach or financial attack. It represents activity detected by the national monitoring infrastructure.

The important point for banks is the scale and volatility of the threat environment.

Threat volumes can rise or fall dramatically from one reporting period to another. That makes continuous monitoring and threat intelligence more valuable than relying exclusively on periodic security reviews.

How Is the Central Bank of Kenya Responding?  

CBK has taken steps to strengthen cybersecurity coordination across Kenya’s banking sector.

One of the most significant developments is the Banking Sector Cybersecurity Operations Centre (BS-SOC), established by CBK in September 2025.

Operating under CBK’s Cyber Fusion Unit, the centre is designed to strengthen capabilities around:

  • Cyber threat intelligence
  • Incident response
  • Digital forensics
  • Cyber investigations
  • Sector-wide information sharing

CBK has also stated that regulated institutions are required to report cybersecurity incidents to the BS-SOC within stipulated timelines under the applicable cybercrime regulations.

This represents a shift from isolated institutional responses toward greater sector-wide cyber resilience.

For banks, the practical implication is clear: cybersecurity programs need to align not only with internal risk frameworks but also with the broader regulatory and intelligence-sharing ecosystem.

The 2026 Cybersecurity Priorities for Kenyan Banks  

There is no single technology that can eliminate banking cyber risk.

Instead, banks need a layered approach covering customers, employees, infrastructure, third parties and regulatory requirements.

Six priorities stand out:  

1. Modernize authentication
Reduce dependence on SMS-only authentication and introduce stronger risk-based controls.

2. Strengthen insider-risk monitoring
Use behavioural analytics and transaction monitoring to identify suspicious activity.

3. Tighten third-party access
Apply rigorous access, monitoring and offboarding standards to vendors and contractors.

4. Build ransomware resilience
Segment critical systems, maintain isolated backups and test recovery procedures.

5. Strengthen threat intelligence
Use sector-wide intelligence and information-sharing mechanisms to identify emerging threats faster.

6. Integrate cyber risk into enterprise risk
Bring technology, fraud, compliance, legal and communications teams into cyber-incident planning.

Conclusion  

Kenya’s banking sector is entering a period where digital growth and cyber risk are advancing together. Reported banking cyber-fraud cases increased from 153 to 353 between 2023 and 2024, while actual losses reached approximately KES 1.59 billion, against a backdrop of billions of cyber-threat events detected across Kenya’s digital infrastructure. Mobile banking, insider access, ransomware and third-party exposure must therefore be treated as interconnected business risks rather than isolated IT issues. With CBK strengthening sector-wide capabilities through the Banking Sector Cybersecurity Operations Centre and national monitoring continuing through KE-CIRT/CC, Kenyan banks have an increasingly clear framework for moving from reactive defense to proactive resilience. The priority for 2026 is not simply to prevent the next attack, but to detect it faster, contain it sooner, recover quicker and protect customer trust throughout the process.

Related Posts

Leave a Reply

Your email address will not be published. Required fields are marked *